3 ms·
I agree someone needs to look into this more directly. The bits he was specifically interested in and wrote most about were the thermography pieces. And that'
by heroprotagonist 2y ago
I agree someone needs to look into this more directly. The bits he was specifically interested in and wrote most about were the thermography pieces. And that's where the focus of the article was. The author notes only skimming the parts he found where the requested permissions were used, given that the experience of the author was not focused in either Android nor Java.
It's not a comprehensive analysis but what is there is very alarming.
There is absolutely NO reason for this app to need MDM_APP_MGMT. This is capability for remote administration of the device, including ability to install additional apps (which is likely where this vector would expand exploitation). We don't see where that permission is used from the few screenshots of non-thermo sections.
Same for a number of the other permissions. For an 'at-a-glance' review, compare this app's requested permissions to those requested by stalkerware in this stalkerware analysis and notice the similarities:
https://andpalmier.com/posts/stalkerware-analysis/#analysis-of-the-sample https://andpalmier.com/posts/stalkerware-analysis/#analysis-...